Master's ThesisAvailable

Privacy-Preserving Anomaly Detection in Multi-Slice 6G Networks

Network slicing in 5G/6G networks allows operators to provide logically isolated networks to different tenants over shared radio, transport, cloud, and core-network infrastructure. Although slices are separated at the service level, they ...

5G/6GSystems

Background and Motivation

Network slicing in 5G/6G networks allows operators to provide logically isolated networks to different tenants over shared radio, transport, cloud, and core-network infrastructure. Although slices are separated at the service level, they may depend on common network functions, edge nodes, links, and orchestration platforms. A compromised tenant or shared component can therefore affect multiple slices through resource exhaustion, signalling abuse, isolation violations, or malicious behaviour in shared network functions.

Detecting such attacks requires correlating telemetry across slices. However, tenant traffic, logs, performance data, and operational information may be commercially sensitive, privacy-relevant, or restricted by administrative boundaries. Centralising all data is therefore often impractical. At the same time, detectors trained independently within each slice may miss distributed attack patterns and cannot easily identify shared causes.

This thesis will investigate collaborative and privacy-preserving methods for detecting and localising inter-slice attacks without requiring tenants to disclose raw operational data. The thesis will explore suitable learning and graph-based techniques, determine what telemetry and infrastructure knowledge are required, and evaluate the approach using representative inter-slice attack scenarios.

Expected Outcomes

This thesis will develop a privacy-preserving framework for detecting and localising inter-slice attacks in 5G and beyond networks. The framework should enable slice-specific anomaly detectors within an operator’s network to collaboratively learn attack patterns without centralising raw tenant traffic, logs, or operational telemetry.

The core contribution will combine distributed learning with contextual information about network slices, shared network functions, RAN and core components, infrastructure dependencies, and observed anomalies. Federated learning, graph neural networks, knowledge graphs, or related techniques may be explored to identify and justify the most suitable design.

The existing knowledge-graph framework in PRISM may be extended to capture slice ownership and RAN components where necessary. This information may support attack correlation, distinguish malicious behaviour from operational failures, and identify the affected slice or shared component.

The framework will be evaluated using representative attack scenarios such as inter-slice resource exhaustion, signalling abuse, slice-isolation violations, compromise of shared network functions etc. Evaluation will compare the proposed solution with baselines using detection accuracy, false-positive rate, localisation capability, communication overhead, scalability, and privacy preservation.

The research will provide practical guidance on when collaborative learning is beneficial for network-slice security, what telemetry and topology information are required, and how privacy, detection performance, and system complexity should be balanced.

Requirements

  • Good understanding of computer networks and 5G/6G mobile communication architecture
  • Knowledge of AI/ML for anomaly detection
  • Programming skills in Python or a similar language
  • Familiarity with Linux, Kubernetes, containers, and cloud-native systems
  • Interest in cybersecurity, distributed systems, and machine learning
  • Experience with federated learning, graph neural networks, knowledge graphs and building network testbeds is a plus

[1] Sehan Samarakoon, Nitinder Mohan, and Fernando Kuipers. PRISM: Cross-Layer Observability Framework for Mobile Core Networks. In 2026 IFIP Networking Conference (IFIP Networking), pp. 1–9. IEEE, 2026.

[2] Iftikhar Rasheed and Hala Mostafa. Federated Learning-Based Anomaly Detection for Zero-Day Attack Prevention in 6G Network Slices. Computer Networks, 2025.

[3] Hedyeh Nazari, Abbas Yazdinejad, Ali Dehghantanha, Fattane Zarrinkalam, and Gautam Srivastava. Symbiotic Federated Learning for Giant AI Threat Detection in 6G-IoT Infrastructures. IEEE Internet of Things Journal, 2025.

Interested in This Topic?

Contact the supervisors with your CV, transcript, and a brief statement of interest.